diff --git a/Engine.Tests/Analyze/BuiltInConditionCatalogTests.cs b/Engine.Tests/Analyze/BuiltInConditionCatalogTests.cs new file mode 100644 index 0000000..f5d8195 --- /dev/null +++ b/Engine.Tests/Analyze/BuiltInConditionCatalogTests.cs @@ -0,0 +1,19 @@ +using Engine; +using System.Linq; +using Xunit; + +namespace Engine.Tests.Analyze +{ + public class BuiltInConditionCatalogTests + { + [Fact] + public void ShouldEnumerateAllBuiltInRules() + { + var rules = BuiltInConditionCatalog.GetRules().ToList(); + + Assert.Equal(12, rules.Count); + Assert.Contains(rules, rule => rule.Name == "amsiBypass"); + Assert.All(rules, rule => Assert.False(string.IsNullOrWhiteSpace(rule.Description))); + } + } +} diff --git a/PowerShellProtect/Analyze/Analyzer.cs b/PowerShellProtect/Analyze/Analyzer.cs index 40f1a18..7590ed5 100644 --- a/PowerShellProtect/Analyze/Analyzer.cs +++ b/PowerShellProtect/Analyze/Analyzer.cs @@ -50,21 +50,7 @@ public Analyzer() new ScriptStringCondition(), }.ToDictionary(m => m.Name.ToLower(), m => m); - _builtInConditions = new List - { - new AmsiBypass(), - new LoggingBypass(), - new DisableDefender(), - new PowerSploit(), - new AssemblyLoad(), - new ReflectionEmit(), - new MarshalClass(), - new PersistentWmi(), - new BloudHound(), - new Kerberoasting(), - new InvokeExpression(), - new Log4J() - }; + _builtInConditions = BuiltInConditionCatalog.Create().ToList(); foreach (var builtInCondition in _builtInConditions) { diff --git a/PowerShellProtect/Analyze/BuiltInConditionCatalog.cs b/PowerShellProtect/Analyze/BuiltInConditionCatalog.cs new file mode 100644 index 0000000..ba389e1 --- /dev/null +++ b/PowerShellProtect/Analyze/BuiltInConditionCatalog.cs @@ -0,0 +1,38 @@ +using System.Collections.Generic; +using System.Linq; +using Engine.Configuration; +using PowerShellProtect.Analyze.Conditions; + +namespace Engine +{ + internal static class BuiltInConditionCatalog + { + internal static IEnumerable Create() + { + return new ICondition[] + { + new AmsiBypass(), + new LoggingBypass(), + new DisableDefender(), + new PowerSploit(), + new AssemblyLoad(), + new ReflectionEmit(), + new MarshalClass(), + new PersistentWmi(), + new BloudHound(), + new Kerberoasting(), + new InvokeExpression(), + new Log4J() + }; + } + + internal static IEnumerable GetRules() + { + return Create().Select(condition => new BuiltInRule + { + Name = condition.Name, + Description = condition.Description + }); + } + } +} diff --git a/PowerShellProtect/Cmdlets/GetConfigurationCommand.cs b/PowerShellProtect/Cmdlets/GetConfigurationCommand.cs index 59df120..a814c5d 100644 --- a/PowerShellProtect/Cmdlets/GetConfigurationCommand.cs +++ b/PowerShellProtect/Cmdlets/GetConfigurationCommand.cs @@ -1,5 +1,7 @@ -using Engine.Configuration; +using Engine; +using Engine.Configuration; using System.Management.Automation; +using System.Linq; namespace PowerShellProtect.Cmdlets { @@ -9,8 +11,11 @@ public class GetConfigurationCommand : PSCmdlet protected override void BeginProcessing() { var config = new Config(); + var configuration = config.GetConfiguration(); - WriteObject(config.GetConfiguration()); + configuration.BuiltInRules = BuiltInConditionCatalog.GetRules().ToList(); + + WriteObject(configuration); } } } diff --git a/PowerShellProtect/Configuration/Configuration.cs b/PowerShellProtect/Configuration/Configuration.cs index 7db3097..f07b2fe 100644 --- a/PowerShellProtect/Configuration/Configuration.cs +++ b/PowerShellProtect/Configuration/Configuration.cs @@ -1,5 +1,6 @@ using System.Collections.Generic; using System.Linq; +using System.Xml.Serialization; namespace Engine.Configuration { @@ -9,6 +10,15 @@ public class Configuration public List Actions { get; set; } = new List(); public BuiltIn BuiltIn { get; set; } = new BuiltIn(); public AiConfiguration AI { get; set; } = new AiConfiguration(); + + [XmlIgnore] + public List BuiltInRules { get; set; } = new List(); + } + + public class BuiltInRule + { + public string Name { get; set; } + public string Description { get; set; } } public class AiConfiguration diff --git a/README.md b/README.md index 07ad330..2d663da 100644 --- a/README.md +++ b/README.md @@ -35,6 +35,16 @@ Install-Module PowerShellProtect Install-PowerShellProtect ``` +## Inspect built-in rules + +`Get-PSPConfiguration` includes the built-in rules that ship with the module. The +`BuiltInRules` property lists each rule's name and description; it is informational +only and is not written into exported configuration XML. + +```powershell +(Get-PSPConfiguration).BuiltInRules | Format-Table Name, Description -Wrap +``` + ## Resources - [License](./LICENSE)